*wheeeeee, let's post responses that are actually incorrect! =D*
Ok, clearly, a client-side validation is useless, as the user is able to go around that very easely. Just use the server-side validation. (In the PHP code.) (Usually the 2 are combined.)
The META-redirect should work, but is not...